Jason Ryan
09/06/2022, 9:46 PMroot/.CommandBox/lib/runwar-4.7.7.jar
? This is box-light by the way. In my Lucee hardening adventure, the last two items striking some red flags are io.undertow:undertow-core
and net.minidev:json-smart-mini
both of which are showing up as included in that .jar file.bdw429s
09/06/2022, 10:24 PMJason Ryan
09/07/2022, 3:26 PMio.undertow:undertow-core
remains unchanged in its vulnerability status. But net.minidev:json-smart-mini
is slightly different - This one no longer shows up under runwar-4.7.7.jar
but it does come up under /root/.CommandBox/lib/json-smart-mini-1.0.8.jar
Jason Ryan
09/07/2022, 3:26 PM.jar
🤔bdw429s
09/07/2022, 4:34 PMJason Ryan
09/07/2022, 4:35 PMJason Ryan
09/07/2022, 4:35 PMbdw429s
09/07/2022, 4:37 PMbdw429s
09/07/2022, 4:37 PMbdw429s
09/07/2022, 4:38 PMJason Ryan
09/07/2022, 4:41 PMbdw429s
09/07/2022, 4:43 PMbdw429s
09/07/2022, 4:43 PMbdw429s
09/07/2022, 4:43 PMJason Ryan
09/07/2022, 4:44 PMJason Ryan
09/07/2022, 4:44 PMA flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up.
bdw429s
09/07/2022, 4:45 PMbdw429s
09/07/2022, 4:46 PMJason Ryan
09/07/2022, 4:46 PMbdw429s
09/07/2022, 4:46 PMbdw429s
09/07/2022, 4:48 PM3.8.7
is the current stable release of XNIObdw429s
09/07/2022, 4:48 PMbdw429s
09/07/2022, 4:48 PMJason Ryan
09/07/2022, 4:48 PMbdw429s
09/07/2022, 4:48 PMJason Ryan
09/07/2022, 4:49 PMbdw429s
09/07/2022, 4:49 PMJason Ryan
09/07/2022, 4:49 PMbdw429s
09/07/2022, 4:49 PMJason Ryan
09/07/2022, 4:50 PM